MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Riss Srl
Riss Srl moma Seismic Station |
|
| Vendors & Products |
Riss Srl
Riss Srl moma Seismic Station |
Tue, 03 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device. | |
| Title | RISS SRL MOMA Seismic Station Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-02-03T22:59:32.539Z
Updated: 2026-02-03T22:59:32.539Z
Reserved: 2026-01-29T16:00:44.404Z
Link: CVE-2026-1632
No data.
Status : Awaiting Analysis
Published: 2026-02-03T23:16:06.457
Modified: 2026-02-04T16:33:44.537
Link: CVE-2026-1632
No data.